Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU103574
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-20147
CWE-ID:
CWE-617 - Reachable Assertion
Exploit availability: No
DescriptionThe vulnerability allows a local application to perform service disruption.
The vulnerability exists due to improper exception handling within Bluetooth. A local application can perform service disruption.
MitigationInstall update from vendor's website.
Vulnerable software versionsMediatek Bluetooth Filter Driver for Windows 10 (Version 1909 or later) - ThinkPad L13 Gen 2, L13 Yoga Gen 2: All versions
MediaTek Bluetooth Driver for Windows 11 64-bit (Version 21H2 or Later) - Yoga AIO 7 27APH8: All versions
MTK Bluetooth Driver for Windows 11 (Version 21H2 or Later) - ThinkCentre Neo 30a 22 Gen 4, Neo 30a 24 Gen 4, Neo 30a 27 Gen 4: All versions
MTK RZ616 BT Driver for Windows 11 (Version 21H2 or Later), 10 (64-bit) - ThinkCentre M90a Gen 3: All versions
MTK7921 BT Driver for Windows 11 (Version 21H2 or Later), 10 (64-bit) - ThinkCentre M90a Gen 3: All versions
MTK RZ616 Bluetooth Driver for Windows 11 (Version 21H2 or Later), 10 (64-bit) - ThinkCentre M90a Pro Gen 3: All versions
MTK RZ616 Bluetooth Driver for Windows 10 (64-bit), 11 (Version 21H2 or later) - ThinkCentre M70a Gen 3: All versions
MTK Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkCentre Neo 70t Gen 3: All versions
MTK7921 Bluetooth Driver for Windows 11 (Version 21H2 or Later), 10 (64-bit) - ThinkCentre M90a Pro Gen 3: All versions
MTK7921 Bluetooth Driver for Windows 10 (64-bit), 11 (Version 21H2 or later) - ThinkCentre M70a Gen 3: All versions
IdeaCentre AIO 3 27ARR9: All versions
MediaTek Bluetooth Driver for Windows 11 64-bit (Version 21H2 or Later) - IdeaCentre AIO 24ARR9, AIO 27ARR9: All versions
IdeaCentre AIO 3 24ARR9: All versions
ThinkCentre M75q Gen 5: All versions
ThinkCentre M75t Gen 5: All versions
ThinkCentre M75s Gen 5: All versions
Thinkpad E16 Gen 1 21JU: All versions
Thinkpad E16 Gen 1 21JT: All versions
ThinkPad E15 Gen 4 21EE: All versions
ThinkPad E15 Gen 4 21ED: All versions
ThinkPad E14 Gen 5 21JS: All versions
ThinkPad E14 Gen 5 21JR: All versions
ThinkPad E14 Gen 4 21EC: All versions
ThinkPad E14 Gen 4 21EB: All versions
ThinkPad Z16 Gen 2 21JY: All versions
ThinkPad Z16 Gen 2 21JX: All versions
ThinkPad Z13 Gen 2 21JW: All versions
ThinkPad Z13 Gen 2 21JV: All versions
ThinkPad S2 Gen 8 Types 21FT China Only: All versions
ThinkPad S2 Yoga Gen 8 21FU: All versions
ThinkPad L15 Gen 4 21H8: All versions
ThinkPad L15 Gen 4 21H7: All versions
ThinkPad L14 Gen 4 21H6: All versions
ThinkPad L14 Gen 4 21H5: All versions
Lenovo 13w Yoga Gen 2 82YS: All versions
Lenovo 13w Yoga Gen 2 82YR: All versions
Lenovo 13w Yoga 82S2: All versions
Lenovo 13w Yoga 82S1: All versions
Yoga AIO 7 27APH8: All versions
ThinkCentre M75t Gen 2: All versions
ThinkCentre M75t Gen 2 11RE: All versions
ThinkCentre M75t Gen 2 11RD: All versions
ThinkCentre M75t Gen 2 11RC: All versions
ThinkCentre M75t Gen 2 11RB: All versions
ThinkCentre M75s Gen 2: All versions
ThinkCentre M75s Gen 2 11RA: All versions
ThinkCentre M75s Gen 2 11R9: All versions
ThinkCentre M75s Gen 2 11R8: All versions
ThinkCentre M75s Gen 2 11R7: All versions
ThinkPad L13 Yoga Gen 2 21AE: All versions
ThinkPad L13 Yoga Gen 2 21AD: All versions
ThinkPad L13 Gen 2 21AC: All versions
ThinkPad L13 Gen 2 21AB: All versions
ThinkPad T16 Gen 2 21K8: All versions
ThinkPad T16 Gen 2 21K7: All versions
ThinkPad T14 Gen 4 21K4: All versions
ThinkPad T14 Gen 4 21K3: All versions
ThinkPad P16s Gen 2 21KA: All versions
ThinkPad P16s Gen 2 21K9: All versions
ThinkPad P14s Gen 4 21K6: All versions
ThinkPad P14s Gen 4 21K5: All versions
ThinkCentre Neo 30a 27 Gen 4: All versions
ThinkCentre Neo 30a 24 Gen 4: All versions
ThinkCentre Neo 30a 22 Gen 4: All versions
ThinkStation P360 Workstation: All versions
ThinkStation P350 Workstation: All versions
ThinkStation P348 Workstation: All versions
ThinkCentre Neo 70t Gen 3: All versions
ThinkCentre M90t Gen 3: All versions
ThinkCentre M90s Gen 3: All versions
ThinkCentre M90q Gen 3: All versions
ThinkCentre M90a Gen 3 Pro: All versions
ThinkCentre M90a Gen 3: All versions
ThinkCentre M80t Gen 3: All versions
ThinkCentre M80s Gen 3: All versions
ThinkCentre M80q Gen 3: All versions
ThinkCentre M70a Gen 3: All versions
ThinkPad L13 Yoga Gen 4 21FS: All versions
ThinkPad L13 Yoga Gen 4 21FR: All versions
ThinkPad L13 Gen 4 21FQ: All versions
ThinkPad L13 Gen 4 21FN: All versions
ThinkPad Z16 Gen 1 21D5: All versions
ThinkPad Z16 Gen 1 21D4: All versions
ThinkPad Z13 Gen 1 21D3: All versions
ThinkPad Z13 Gen 1 21D2: All versions
ThinkStation P340 Workstation: All versions
MTK BlueTooth Driver for Windows 11 (Version 21H2 or Later) - ThinkStation P348: before 24.20.3.38/24.40.2.216/24.10.5.7
Mediatek Bluetooth Driver for Windows 10 (Version 21H2 or later) and 11 (Version 21H2 or Later) - ThinkStation P348: before 24.20.3.38/24.40.2.216/24.10.5.7
MediaTek Bluetooth Driver for Windows 11 (Version 21H2 or later), 10 (Version 21H2 or later) - ThinkStation P340: before 24.20.3.38/24.40.2.216/24.10.5.7
MediaTek Bluetooth Driver for Windows 11 (Version 21H2 or later) and 10 64-bit (Version 21H2 or later) - ThinkStation P350: before 24.20.3.38/24.40.2.216/24.10.5.7
MediaTek MT7921 Bluetooth Driver for Windows 10 (Version 21H2) - ThinkStation P340: before 24.20.3.38/24.40.2.216/24.10.5.7
RZ616 Bluetooth Driver for Windows 11 (Version 21H2 or later), 10 64-bit (Version 21H2 or later) - ThinkPad: before 25.40.2.217
Mediatek AMD RZ616 Bluetooth Filter Driver for Windows 11 (Version 21H2 or later) and 10 (Version 21H2 or later) - ThinkPad L14 Gen 4, L15 Gen 4: before 24.40.2.215
RZ616 Bluetooth Driver for Windows 11 (Version 21H2 or Later), 10 (Version 21H2 or later) - ThinkPad E14 Gen 4, E15 Gen 4: before 25.40.2.217
RZ616 Bluetooth Adapter Driver for Windows 11 (Version 21H2 or later), 10 (Version 21H2 or later) - ThinkPad Z13 (Type 21D2, 21D3), Z16 (Type 21D4, 21D5): before 24.40.2.216
Bluetooth Driver for Windows 11 (Version 22H2 or later) - Lenovo 13w Yoga Gen 2 (Type 82YR, 82YS): before 24.40.2.215
Bluetooth Driver for Windows 10 (Version 22H2 or later) - Lenovo 13w Yoga Gen 2: before 24.40.2.215
Bluetooth Driver for Windows 11 (Version 21H2 or later) - Lenovo 13w Yoga (Type 82S1, 82S2): before 24.40.2.215
Bluetooth Driver for Windows 10 64-bit (Version 21H2 or later) - Lenovo 13w Yoga (Type 82S1, 82S2): before 24.40.2.215
Mediatek Bluetooth Driver for Windows 10 (64-bit) - ThinkCentre Neo 70t Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK BlueTooth Driver for Windows 10 (64-bit) - ThinkCentre M90s Gen 3, M90t Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK BlueTooth Driver for Windows 10 (64-bit) - ThinkCentre M90q Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
Mediatek Bluetooth Driver for Windows 10 (64-bit) - ThinkCentre M80s Gen 3, M80t Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
Mediatek Bluetooth Driver for Windows 10 (64-bit) - ThinkCentre M80q Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or Later) - ThinkCentre M75s Gen 2, M75t Gen 2: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK BlueTooth Driver for Windows 11 (Version 21H2 or later) - ThinkCentre M90s Gen 3, M90t Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkCentre M90q Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkCentre M80s Gen 3, M80t Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or later) - ThinkCentre M80q Gen 3: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 10 64-bit - ThinkCentre M75t Gen 2, M75s Gen 2: before 24.20.3.38/24.40.2.216/24.10.5.7
Mediatek Bluetooth Driver for Windows 10 (64-bit) IOT - Desktop, WorkStation: before 24.20.3.38/24.40.2.216/24.10.5.7
Mediatek Bluetooth Driver for Windows 10 (64-bit) - ThinkCentre M75t Gen 2, M75s Gen 2: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK BlueTooth Driver for Windows 11 IOT (Version 24H2) - ThinkCentre M75s Gen 5, M75t Gen 5: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or Later) - ThinkCentre M75s Gen 5: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 11 (Version 21H2 or Later) - ThinkCentre M75t Gen 5, M75s Gen 5: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 10 (64-bit) - ThinkCentre M75q Gen 5: before 24.20.3.38/24.40.2.216/24.10.5.7
MTK Bluetooth Driver for Windows 10 64-bit - ThinkCentre M75t Gen 5, M75s Gen 5: before 24.20.3.38/24.40.2.216/24.10.5.7
CPE2.3https://support.lenovo.com/us/en/product_security/LEN-182569
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.